New bugs and patches from MS…

Microsoft Windows OLE Automation Array Remote Code Execution Vulnerability.

Description: https://www.us-cert.gov/ncas/alerts/TA14-318B

Exploit for it: http://packetstorm.igor.onlinedirect.bg/1411-exploits/ms14_064_packager_run_as_admin.rb.txt

And another bug that allows gaining domain administrator privileges:

http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about-cve-2014-6324.aspx

There was also a mishap: MS14-066 causes problems with SQL and IIS. That is what happens when instead of focusing on patching, you add new algorithms…

http://www.infoworld.com/article/2849292/operating-systems/more-patch-problems-reported-with-the-ms14-066-kb-2992611-winshock-mess.html